If you work for the FBI, your employer says you should just assume your personal information was stolen by hackers, according to an internal memo reviewed by the New York Times. “We are operating under the premise that the threat actor is also exfiltrating [personally identifiable information] of all F.B.I. employees,” the memo apparently says.
The humiliating ShinyHunters hack, originally reported on Tuesday of last week, was a bit like working for Orkin and finding out that you and all your coworkers have had your personal data stolen by termites. The initial hack caused the FBI jobs portal to display a banner saying “This site has been seized by ShinyHunters.” ShinyHunters told 404 Media, who broke the news of the attack, “We hacked the FBI. We hold data on all FBI employees and applicants.”
According to the Times’ peek at the FBI’s internal communications, that does not appear to have been an exaggeration.
The memo outlines next steps including what the Times calls “virtual briefings” still to come, and includes entreaties to be on the lookout for suspicious text messages or calls from unknown numbers. Employees should, the memo apparently says, create new voice mail greetings with AI voices.
A public statement from the FBI on Monday says (per the Times) the bureau is “working around the clock to investigate the cyber incident involving FBIJobs.gov and is in regular communication with anyone who may be impacted — including multiple bureau-wide communications within 24 hours of public reporting.”
It adds, “The F.B.I. treats the security of its information and the safety of its work force as top priorities, and our investigation is ongoing.” That’s comforting, since the organization in question is allegedly some sort of bureau of investigation.